Rp1
Medium
- Category
- MCP Rug Pull
- Confidence
- 70% confidence
- Finding
- npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Security audit
Security checks for vulnerabilities and agentic risk
This skill coherently connects an agent to SocQ for public Amazon research, with disclosed external API use and reasonable guardrails around credentials, billing, and scope.
Install this only if you are comfortable using SocQ as a third-party service for public Amazon research. Set SOCQ_API_KEY securely, avoid placing secrets or private business data in prompts or URLs, confirm paid or large collection jobs before running them, and prefer a pinned or already-installed SocQ CLI where your environment requires tighter supply-chain control.
value: "socq"
description: "Hosted SocQ Amazon data tools"
transport: "streamable_http"
url: "https://api.socq.ai/mcp?platforms=amazon"value: "socq"
description: "Hosted SocQ Amazon data tools"
transport: "streamable_http"
url: "https://api.socq.ai/mcp?platforms=amazon"Detected: suspicious.exposed_secret_literal